1
hazman
PopnupBlog index.php multiple variables Cross-Site Scripting
  • 2008/8/28 13:14

  • hazman

  • Just popping in

  • Posts: 1

  • Since: 2005/7/29


You don't seem to have a security forum so I don't know where to post this. Feel free to move the post.

PopnupBlog index.php multiple variables Cross-Site Scripting

PopnupBlog contains a flaw that allows a remote cross site scripting attack.This flaw exists because
the application does not validate 'param' , 'cat_id' and 'view' variables upon submission to 'index.php' script.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within
the trust relationship between the browser and the server, leading loss ofintegrity.

More...

Login

Who's Online

215 user(s) are online (159 user(s) are browsing Support Forums)


Members: 0


Guests: 215


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits